WPA3-Enterprise (802.1X/EAP), Certificate for Internal Authentication Server

Options
PeterG_MCC
PeterG_MCC Posts: 2  Freshman Member

I’m running a Zyxel USG FLEX 700H with WPA3-Enterprise (802.1X/EAP) for my Wi-Fi network. However, every time a client tries to join, it is prompted to accept an “example server certificate”—which is already expired—rather than a valid, CA-signed certificate or a valide self signed certificate.

On my ATP 700 it was straightforward to select which certificate the internal internal Authentication Server should use.

Can anyone please tell me where I can choose the certificate for the internal Authentication Server on a USG FLEX 700H?

Many Thanks in advance

All Replies

  • Zyxel_Tina
    Zyxel_Tina Posts: 82  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 5 Answers First Comment

    Hi @PeterG_MCC,

    Welcome to Zyxel Community!

    Regarding your question about selecting the certificate for the internal Authentication Server on the USG FLEX 700H. We are currently working on confirming the details for you. Once we have accurate information, we will update you promptly. We appreciate your patience and understanding.

    Zyxel Tina

  • Zyxel_Tina
    Zyxel_Tina Posts: 82  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 5 Answers First Comment

    Hi @PeterG_MCC,

    Thank you for your patience.

    After checking, we'd like to share the following updates regarding the certificate behavior on the USG FLEX 700H, the ability to manually assign or import a different certificate for the internal authentication server is not yet available. We've submitted this request as a feature enhancement for future releases.

    Please also note:

    The V1.35 firmware is scheduled for release soon. Please stay tuned for updates on our News and Release.

    We suggest removing (forgetting) the existing SSID on affected client devices and reconnecting to rebuild the connection using the updated certificate.

    Zyxel Tina